Two connected learning models Explore the linear model at KillChains.com

Trace every assurance claim to its limits

Autonomy Assurance Case and Evidence Traceability Lab

Inspect how a bounded synthetic assurance case connects claims, evidence, assumptions, counterclaims, defeaters, verification, residual risk, accountable review, and invalidating change—without turning traceability into certification.

Research basis KW-RPT-011 KW-RPT-012 KW-RPT-014 KW-RPT-028

Reasoned argument, not a score

An assurance case explains why a bounded claim may be relied upon—and exactly what would make that reliance stop.

A claim graph is useful only when supporting evidence, contradictory evidence, assumptions, review responsibility, unresolved risk, and change triggers remain visible. Completing the graph does not prove that a real autonomous system is safe, ready, lawful, certified, or authorized.

Case
Fixed synthetic claims and trace links
Change
Allowlisted invalidating events
Result
Supported, qualified, unresolved, suspended, or withdrawn
Excluded
Certification, percent-safe scores, real missions, force authority

Assurance-case anatomy

Keep the elements separate so the reasoning can be challenged.

The public model uses one fixed catalog. It accepts no free-form claim, uploaded evidence, external URL, model file, platform record, target, or operational data.

01

Claims and subclaims

State the bounded proposition and decompose it into independently reviewable dependencies.

02

Evidence

Record provenance, date, independence group, scope, review state, and whether the record supports or contradicts.

03

Assumptions

Expose the environmental, authority, software, data, and human conditions on which the claim depends.

04

Counterclaims and defeaters

Preserve reasons the argument could be wrong and events that suspend or withdraw a claim.

05

Verification and residual risk

Show what was actually tested, what must be rerun, and what remains unresolved after testing.

06

Review and change control

Name accountable roles and require re-review when software, models, configuration, authority, timing, sources, or mission bounds change.

Change-impact exercise

Select a fixed scenario or build an allowlisted change set.

Synthetic only

Scenario brief

Reviewed bounded baseline

Inspect the fixed assurance case before any invalidating change. Several claims remain qualified because contradictory evidence and residual risk are deliberately preserved.

Lesson
A complete graph can support bounded reliance without becoming a certification or claim of safety.
Invalidating change events

Choose only from fixed public change records. A request is capped at five events and cannot add arbitrary claims or evidence.

Restore reviewed baseline

The normal POST form is complete without JavaScript. Enhanced mode calls only the same-origin calculation API. No submission is stored, profiled, or transmitted externally.

Current top-level disposition

Bounded support remains qualified

Supported with qualifications

The fixed baseline remains a qualified, bounded teaching claim. Counterclaims, assumptions, and residual risks remain visible and prevent any certification inference.

3Supported
5Qualified
0Unresolved
0Suspended
0Withdrawn

Suspended claims

None in this fixed state

Withdrawn claims

None in this fixed state

Mandatory re-review actions

  • Monitor the declared change triggers and retain all qualifications, counterclaims, and residual risks.
Server-rendered traceability analysis ready. No certification, readiness, legality, or authority created.

Claim structure

The top-level proposition inherits the limits of every critical subclaim.

A suspended or withdrawn dependency cannot be averaged away by unrelated technical evidence.

C-001Supported with qualifications

Top-level bounded-assurance claim

The fictional autonomous support function can be relied upon only for observation, state estimation, recommendation, and already-approved non-force task coordination within the declared evidence, software, authority, supervision, containment, and recovery bounds.

Scope
Synthetic public teaching environment; no real platform, target, mission, weapon, or force authorization.
Parent
Top level
Evidence
E-001E-002E-012
Assumptions
A-001A-007
Counterclaims
CC-001
Defeaters
D-001

Current reasoning

  • Baseline review state: Supported with qualifications.
C-010Supported within declared bounds

Function and mission bounds are explicit

The function cannot silently expand beyond the declared non-force support tasks or change its own governance.

Scope
Declared function contract, excluded consequences, safe states, and mission-bound controls.
Parent
C-001
Evidence
E-001E-002
Assumptions
A-001
Counterclaims
CC-001
Defeaters
D-001

Current reasoning

  • Baseline review state: Supported within declared bounds.
C-020Supported with qualifications

Evidence is traceable, current, and sufficiently independent

Every observation and derived product used by the function carries reviewable provenance, date, scope, transformation, and independence information.

Scope
Fixed synthetic evidence catalog and data-lineage checks.
Parent
C-001
Evidence
E-003E-004
Assumptions
A-002
Counterclaims
CC-002
Defeaters
D-002

Current reasoning

  • Baseline review state: Supported with qualifications.
C-030Supported with qualifications

Software, model, and configuration state are approved and consistent

Only signed, reviewed, compatible artifacts and declared configurations may contribute to the bounded function.

Scope
Synthetic artifact manifest, version baseline, rollback, and mixed-version tests.
Parent
C-001
Evidence
E-005E-006
Assumptions
A-003
Counterclaims
CC-003
Defeaters
D-003D-008

Current reasoning

  • Baseline review state: Supported with qualifications.
C-040Supported within declared bounds

Authority is current, scoped, and independently enforced

Technical connectivity, model confidence, and task availability cannot create or renew authority.

Scope
Synthetic authority record, expiry, revocation, and scope checks.
Parent
C-001
Evidence
E-007
Assumptions
A-004
Counterclaims
CC-004
Defeaters
D-004

Current reasoning

  • Baseline review state: Supported within declared bounds.
C-050Supported with qualifications

Human review remains meaningful in practice

A responsible reviewer has enough time, evidence access, comprehension, workload capacity, and intervention power to reject, pause, or redirect the function.

Scope
Fixed interface, workload, timed-intervention, and rejection-path trials.
Parent
C-001
Evidence
E-008E-009
Assumptions
A-005
Counterclaims
CC-005
Defeaters
D-005

Current reasoning

  • Baseline review state: Supported with qualifications.
C-060Supported within declared bounds

Safe state, containment, and quarantine remain available

Suspect inputs, artifacts, nodes, and dependent products can be isolated before they propagate into consequential action.

Scope
Synthetic hold, quarantine, rollback, and dependent-product invalidation paths.
Parent
C-001
Evidence
E-010
Assumptions
A-006
Counterclaims
None
Defeaters
D-006

Current reasoning

  • Baseline review state: Supported within declared bounds.
C-070Supported with qualifications

Recovery, reconciliation, and change monitoring preserve claim validity

Reconnection, rollback, or a new release cannot restore reliance until task ownership, timing, evidence, versions, authority, and claim dependencies are reconciled and re-reviewed.

Scope
Synthetic rejoin ledger, change-impact rules, and mandatory re-review triggers.
Parent
C-001
Evidence
E-011E-012
Assumptions
A-006A-007
Counterclaims
CC-006
Defeaters
D-007

Current reasoning

  • Baseline review state: Supported with qualifications.

Text alternative to the claim graph

Every relationship is available as a semantic ledger.

The ledger prevents a visual connector from becoming the only way to understand why one record supports, qualifies, challenges, or invalidates another.

FromRelationshipTo
E-001supports or qualifiesC-001
E-002supports or qualifiesC-001
E-012supports or qualifiesC-001
A-001boundsC-001
A-007boundsC-001
V-001testsC-001
V-002testsC-001
CC-001challengesC-001
R-003qualifiesC-001
R-004qualifiesC-001
R-006qualifiesC-001
E-001supports or qualifiesC-010
E-002supports or qualifiesC-010
A-001boundsC-010
V-001testsC-010
V-002testsC-010
CC-001challengesC-010
R-003qualifiesC-010
E-003supports or qualifiesC-020
E-004supports or qualifiesC-020
A-002boundsC-020
V-003testsC-020
CC-002challengesC-020
R-001qualifiesC-020
E-005supports or qualifiesC-030
E-006supports or qualifiesC-030
A-003boundsC-030
V-004testsC-030
CC-003challengesC-030
R-005qualifiesC-030
E-007supports or qualifiesC-040
A-004boundsC-040
V-005testsC-040
CC-004challengesC-040
R-004qualifiesC-040
E-008supports or qualifiesC-050
E-009supports or qualifiesC-050
A-005boundsC-050
V-006testsC-050
CC-005challengesC-050
R-002qualifiesC-050
E-010supports or qualifiesC-060
A-006boundsC-060
V-007testsC-060
R-003qualifiesC-060
E-011supports or qualifiesC-070
E-012supports or qualifiesC-070
A-006boundsC-070
A-007boundsC-070
V-008testsC-070
CC-006challengesC-070
R-006qualifiesC-070
C-010supports parentC-001
C-020supports parentC-001
C-030supports parentC-001
C-040supports parentC-001
C-050supports parentC-001
C-060supports parentC-001
C-070supports parentC-001

Evidence ledger

Evidence is dated, scoped, reviewable, and change-sensitive.

Support and contradiction can coexist. A current digest or signature does not prove relevance, independence, or fitness for a changed purpose.

EvidenceProvenance and dateIndependenceScopeSupports / contradictsCurrent state
E-001Reviewed bounded-function contractDefines what the teaching system may and may not do; it creates no real authority.Synthetic requirements registry2026-08-02 · review: revieweddesign-authorityNon-force support functions, excluded actions, safe states, and mission bounds.Supports C-001C-010
Contradicts None
currentThe record remains attached to the reviewed synthetic baseline.
E-002Negative boundary and self-governance testsFixed negative tests confirm that prohibited requests are not accepted by the model.Independent synthetic verification harness2026-08-02 · review: reviewedindependent-testRequests for force selection, mission expansion, arbitrary claims, and governance change.Supports C-001C-010
Contradicts None
currentThe record remains attached to the reviewed synthetic baseline.
E-003Evidence-lineage audit sampleShows complete lineage for the fixed baseline evidence set.Synthetic data-steward ledger2026-08-02 · review: revieweddata-governanceSource identity, time, transformation, review state, and permitted use.Supports C-020
Contradicts None
currentThe record remains attached to the reviewed synthetic baseline.
E-004Source-independence and correlation reviewFinds adequate diversity for the exercise but leaves uncertainty about hidden common-mode dependence.Independent assurance review2026-08-02 · review: provisionalindependent-reviewCommon collection lineage and repeated reporting across the evidence set.Supports C-020
Contradicts C-020
currentThe record remains attached to the reviewed synthetic baseline.
E-005Signed artifact and configuration manifestIdentifies the approved baseline used by the fixed verification record.Synthetic approved-update registry2026-08-02 · review: reviewedchange-controlSoftware, model, configuration, dependency, signature, and rollback identifiers.Supports C-030
Contradicts None
currentThe record remains attached to the reviewed synthetic baseline.
E-006Mixed-version and rollback exerciseThe system detected the fixed version split, but unseen combinations remain outside the evidence.Independent failure-injection lab2026-08-02 · review: reviewedindependent-testVersion mismatch detection, rollback, and dependent-product invalidation.Supports C-030
Contradicts C-030
currentThe record remains attached to the reviewed synthetic baseline.
E-007Authority expiry and revocation testThe fixed model holds the function when the authority record expires.Synthetic authority-gate verification2026-08-02 · review: reviewedauthority-reviewScope, expiry, revocation, and separation of capability from permission.Supports C-040
Contradicts None
currentThe record remains attached to the reviewed synthetic baseline.
E-008Timed reviewer intervention trialA reviewer can interrupt the fixed baseline workflow under the tested workload and timing.Synthetic human-factors evaluation2026-08-02 · review: reviewedhuman-factorsEvidence access, comprehension prompt, pause, reject, and redirect controls.Supports C-050
Contradicts None
currentThe record remains attached to the reviewed synthetic baseline.
E-009Overload and compressed-review challengeDemonstrates that nominal human-on-the-loop control can fail under workload and time pressure.Independent human-factors red team2026-08-02 · review: reviewedindependent-reviewHigh alert volume, short intervention window, and evidence-ordering effects.Supports None
Contradicts C-050
currentThe record remains attached to the reviewed synthetic baseline.
E-010Quarantine and dependent-product invalidation exerciseThe fixed scenario isolates a suspect artifact and invalidates dependent outputs.Synthetic cybersecurity test harness2026-08-02 · review: reviewedindependent-testSuspect update isolation, product lineage tracing, rollback, and safe-state entry.Supports C-060
Contradicts None
currentThe record remains attached to the reviewed synthetic baseline.
E-011Partition rejoin and task-ownership reconciliation exerciseThe fixed model requires reconciliation before shared operation resumes.Synthetic autonomy-assurance lab2026-08-02 · review: reviewedindependent-testTask leases, clocks, authority, versions, state conflicts, and rejoin acknowledgment.Supports C-070
Contradicts None
currentThe record remains attached to the reviewed synthetic baseline.
E-012Residual-unknown and review-responsibility recordPrevents completion of the traceability graph from being represented as certification.Independent assurance review2026-08-02 · review: reviewedindependent-reviewUnresolved unknowns, accountable reviewers, and re-review triggers.Supports C-001C-070
Contradicts None
currentThe record remains attached to the reviewed synthetic baseline.

Limits and challenge

Assumptions and counterclaims remain first-class records.

They are not footnotes to be hidden after the positive argument.

Assumptions and environmental bounds

A-001current

Mission scope remains non-force and unchanged

No target selection, weapon assignment, force authorization, or governance expansion.

The declared assumption has not been invalidated by the selected change set.
A-002current

Evidence sources and lineage contracts remain unchanged

No silent data-source substitution, transformation change, or loss of provenance.

The declared assumption has not been invalidated by the selected change set.
A-003current

Approved artifact baseline remains unchanged

Software, model, configuration, dependency, and rollback identifiers match the tested baseline.

The declared assumption has not been invalidated by the selected change set.
A-004current

Authority remains current and in scope

The authority record has not expired, been revoked, or been applied outside its declared function.

The declared assumption has not been invalidated by the selected change set.
A-005current

Human workload and intervention time remain within tested bounds

The reviewer has adequate time, evidence access, comprehension, and interruption power.

The declared assumption has not been invalidated by the selected change set.
A-006current

Containment and reconciliation services remain available

Safe state, quarantine, rollback, signed logs, and rejoin controls are reachable.

The declared assumption has not been invalidated by the selected change set.
A-007current

No unobserved external side effect changes the case

The public synthetic model does not represent all environmental, organizational, or legal conditions.

The declared assumption has not been invalidated by the selected change set.

Counterclaims and contradictory propositions

CC-001challenge

Task completion is not proof of boundedness

A system may complete the demonstrated task while still containing untested pathways or hidden scope expansion.

Challenges C-001C-010
CC-002challenge

Visible metadata may still conceal common lineage

Two apparently separate reports can depend on one collection stream or transformation service.

Challenges C-020
CC-003challenge

A signed artifact can still be unsuitable

Authenticity proves origin and integrity, not correctness, compatibility, or fitness for the changed context.

Challenges C-030
CC-004challenge

An approval record may be stale or outside scope

A technically valid record does not apply after expiry, revocation, or mission-bound change.

Challenges C-040
CC-005challenge

Nominal human control can be procedural ratification

An operator cannot exercise meaningful judgment without enough time, evidence, capacity, and rejection power.

Challenges C-050
CC-006challenge

Reconnection is not restoration

A restored link does not renew authority, resolve duplicate ownership, repair lineage, or validate products created while partitioned.

Challenges C-070

Invalidating change

A changed system must not inherit an unchanged assurance claim.

Software, model, configuration, authority, timing, source, mission-bound, human-control, containment, and reconciliation changes each have their own review impact.

Selected change events

BASELINEmonitored

No invalidating change selected

The qualified baseline still depends on continued monitoring of every declared trigger.

Active defeaters

NONEbaseline

No active change-triggered defeater

Counterclaims and residual risks remain active qualifications even when no hard defeater is selected.

Verification and residual risk

Passing evidence can expire; residual risk never becomes zero by declaration.

Every changed dependency identifies which activity must be rerun and which uncertainty remains outside the fixed exercise.

Verification activities

V-001passed

Function-contract inspection

Review the declared function, exclusions, authority boundary, and safe states.

The recorded result applies only to the reviewed baseline.
V-002passed

Negative boundary test

Submit fixed prohibited requests and verify rejection without server state or external calls.

The recorded result applies only to the reviewed baseline.
V-003qualified

Provenance and independence audit

Trace source, time, transformation, review, and independence group for each evidence record.

The recorded result applies only to the reviewed baseline.
V-004qualified

Artifact, compatibility, and rollback test

Verify signed baseline, mixed-version detection, rollback, and dependent-output invalidation.

The recorded result applies only to the reviewed baseline.
V-005passed

Authority expiry and revocation test

Expire or revoke the fixed authority record and verify that technical recovery cannot renew it.

The recorded result applies only to the reviewed baseline.
V-006qualified

Timed human-intervention test

Measure evidence access, comprehension, workload, pause, reject, and redirect under fixed conditions.

The recorded result applies only to the reviewed baseline.
V-007passed

Quarantine and safe-state exercise

Inject a suspect artifact and verify isolation, hold, rollback, and dependent-product tracing.

The recorded result applies only to the reviewed baseline.
V-008qualified

Partition rejoin and change-impact exercise

Compare signed state, task leases, clocks, versions, authority, and claim dependencies before resumption.

The recorded result applies only to the reviewed baseline.

Residual risks and unknowns

R-001retained

Hidden correlation among evidence sources

Public metadata may not reveal every shared collection or transformation dependency.

Retain as an explicit limitation and seek genuinely independent corroboration.
R-002retained

Human performance varies beyond the fixed trial

Workload, fatigue, experience, interface familiarity, and stress can change intervention quality.

Use recurring human-factors testing and conservative hold thresholds.
R-003retained

Untested interaction and emergent behavior

A finite synthetic case cannot cover every combination of node, change, failure, and organizational response.

Maintain abstention, monitoring, containment, and independent red-team testing.
R-004retained

Legal and command context is not established by this lab

Technical evidence cannot determine real-world lawfulness, target status, proportionality, or command permission.

Require separate accountable legal and command review for any real system.
R-005retained

Supply-chain state outside the public record

The synthetic manifest cannot establish real hardware, firmware, model, or supplier integrity.

Use authentic provenance, reproducible builds, inspection, and continuous monitoring in real assurance.
R-006retained

Environmental and mission drift

A valid case can become stale when data sources, tempo, environment, authorities, or mission bounds change.

Monitor declared change triggers and suspend reliance until re-review.

Accountable review

Re-review belongs to named roles, not to an anonymous workflow.

The selected change set determines which reviewers must participate before a suspended claim can return to a current state.

case-owner

Assurance case owner

Maintains claim scope, dependencies, review state, and withdrawal decisions.

independent-reviewer

Independent assurance reviewer

Challenges the reasoning, checks traceability, and confirms that counterevidence is not hidden.

Lifecycle method

Assurance is a maintained argument, not a one-time document.

The case must be monitored, challenged, suspended, revised, and sometimes withdrawn as its dependencies change.

  1. 1

    Bound the claim

    State the exact function, environment, consequence, evidence threshold, authority, and excluded use.

  2. 2

    Build traceability

    Connect each subclaim to evidence, assumptions, counterclaims, defeaters, verification, residual risks, and reviewers.

  3. 3

    Challenge the argument

    Seek contradictory evidence, common-mode dependence, negative cases, and failure conditions rather than confirmation alone.

  4. 4

    Monitor invalidating change

    Watch software, model, configuration, authority, timing, source, mission, human-control, and recovery contracts.

  5. 5

    Suspend or withdraw

    Stop relying on affected claims before re-review; do not allow an old report to authorize a changed system.

  6. 6

    Re-review with accountability

    Rerun affected verification, resolve counterevidence, record residual risk, and obtain explicit reviewer decisions.

Answer-ready summary

Direct answers

What is an autonomy assurance case?

It is a maintained, reviewable argument connecting a bounded top-level claim to subclaims, evidence, assumptions, challenges, verification, residual risk, accountable reviewers, and events that invalidate the argument.

Read the supporting page

What happens when the system changes?

The affected evidence, assumptions, and tests are marked invalid or out of scope; dependent claims are suspended or withdrawn; and named reviewers must complete re-review before reliance resumes.

Read the supporting page

Does a complete assurance case certify safety or readiness?

No. Traceability organizes reasoning and makes its limits visible. It does not create certification, compliance, readiness, safety, legality, mission success, target confidence, or force authority.

Read the supporting page